backend · easy

Session cookie

Server-side session id (or signed payload) stored in a cookie so later requests know who is logged in.

Where you see it

Rails `session[]` is typically a signed/encrypted cookie. `flash` is a one-request session slice for “Post created.” HttpOnly and Secure flags matter. Contrast with JWTs in localStorage — different tradeoffs.

Why it matters

Most HTML fullstack apps still authenticate with sessions. Take-homes that skip CSRF and cookie flags fail production review.

Tags: rails, nodejs